---
title: "Interaction between the Digital ID Act and the Privacy Act"
source: "https://www.digitalidsystem.gov.au/sites/default/files/2024-11/digital_id_guidance_5_-_interaction_between_the_digital_id_act_and_the_privacy_act.pdf"
collection: "digital-id-accreditation"
guidance_commit: "db3111cd9d11643ac08b34b4d75b0d0d983ca388"
---

Interaction between the Digital ID Act and the
Privacy Act

Contents
Privacy obligations of an accredited entity                                           1
    Privacy safeguards in the Digital ID Act                                          1
    Privacy obligations in the Privacy Act                                            1
    Table summarising the interactions between the Digital ID Safeguards and Privacy Act
    Australian Privacy Principles                                                     2
                                                                                     November 2024


 Privacy obligations of an accredited entity
 Privacy protections are built into Australia’s Digital ID system. When providing accredited
 services, accredited entities must comply with the privacy safeguards in the Digital ID Act
 2024 (Digital ID Act). These safeguards are in addition to, and build on, the Australian Privacy
 Principles (APPs) contained in the Privacy Act 1988 (Privacy Act) (or equivalent state or
 territory laws).

 All accredited entities will be required to comply with the following privacy requirements:

1. Privacy obligations of an accredited entity

           be subject to the federal Privacy Act or an comparable state or territory law or enter
           into an APP-equivalent agreement

           comply with the federal Notifiable Data Breaches scheme, unless they are covered
           by a comparable state or territory scheme
           comply with the 13 additional privacy safeguards in the Digital ID Act


 Privacy safeguards in the Digital ID Act
 The Digital ID Act contains 13 additional privacy safeguards that apply to all accredited
 entities and that build on the privacy safeguards contained in the Privacy Act (or equivalent
 state or territory laws). The 13 additional privacy safeguards:

     -    regulate accredited entities’ handling of biometric information and certain attributes
          when providing accredited services;
     -    outline requirements to obtain express consent for the handling of biometric
          information and certain other attributes of individuals; and
     -    limit the handling of personal information for data profiling, enforcement purposes
          and marketing.

 Privacy obligations in the Privacy Act
 In addition to complying with the 13 additional privacy safeguards in the Digital ID Act, APP
 entities and certain other accredited entities will have to comply with privacy obligations in
 the Privacy Act, in particular the 13 Australian Privacy Principles (APPs), when providing
 accredited services. These accredited entities are:

     -    APP entities (including organisations with an annual turnover of more than $3 million
          and Australian Government agencies)


 Interaction between the Digital ID Act and the Privacy Act                                  Page 1
 oaic.gov.au
                                                                                                               November 2024


        -     entities that have entered an APP-equivalent agreement,1 and
        -     small business operators that are accredited entities.2

 The Privacy Act obligations will not apply to accredited state or territory entities that are not
 APP entities, when the entity is instead subject to state or territory privacy legislation that
 provides protection comparable to the Privacy Act.

 Table summarising the interactions between the Digital ID Safeguards and Privacy
 Act Australian Privacy Principles
 The following table provides a brief outline of how each Digital ID privacy safeguard and APP
 interact. For further information on the mandatory requirements of the APPs, see the OAIC’s
 Australian Privacy Principles guidelines.

2. Safeguard                     3. Relevant APP          4. Interaction between safeguard and APP

     Section 44:                     Collection – APPs 3      By prohibiting collection of certain attributes, s
     Prohibition on                  and 4                    44 overrides3 APP 3.3 and 3.4 in relation to the
     collection of certain                                    collection of those attributes listed in s 44 (APP
     attributes                                               3 generally allows collection of sensitive
                                                              information where certain conditions are met).

                                                              For other types of sensitive information that
                                                              are not listed in s 44, APP 3.3 and 3.4 will apply
                                                              to collection.

                                                              If an accredited entity collects a prohibited
                                                              attribute which it did not solicit, the entity can
                                                              avoid being in breach of s 44 if it destroys the
                                                              attribute as soon as practicable after becoming
                                                              aware of the collection. In relation to the
                                                              collection of unsolicited information generally,
                                                              an accredited entity must still comply with APP
                                                              4.
     Section 45: Express Disclosure – APP 6                   For disclosure of the specified attributes listed
     consent for                                              in s 45, the provision sets out how disclosure
     disclosure of certain                                    can occur and overrides the operation of APP 6
     attributes to relying                                    as express consent is the only basis for
     parties                                                  disclosure of these attributes to relying parties.


 1
     s 34 and s 36(2)(c) of the Digital ID Act.
 2
     s 33 and s 35A of the Digital ID Act.
 3
  For the purposes of this guidance, 'overrides' is used to convey situations where a safeguard imposes stricter requirements
 than the corresponding APPs. This term does not alter the legal position that both the Digital ID Act and the Privacy Act apply
 concurrently.


 Interaction between the Digital ID Act and the Privacy Act                                                              Page 2
 oaic.gov.au
                                                                                                   November 2024


 Section 46:           Disclosure – APP 6                    For disclosure of restricted attributes of
 Prohibition of                                              individuals to relying parties, s 46 will override
 disclosure of                                               the operation of APP 6 as express consent is the
 restricted attributes                                       only basis for disclosing these attributes.
 without express
                                                             Restricted attributes are defined in s 11 of the
 consent
                                                             Digital ID Act.

                                                             S 46 introduces an additional limitation on
                                                             disclosure of restricted attributes when the
                                                             disclosure is to a relying party that is not a
                                                             ‘participating relying party’ – the accredited
                                                             entity may only disclose restricted attributes if
                                                             the accredited entity’s accreditation conditions
                                                             authorise disclosure to the relying party.
 Section 47:          Disclosure – APP 6                     The restrictions in s 47 on disclosing a unique
 Restriction of                                              identifier overrides the operation of APP 6. S 47
 disclosure of unique                                        prohibits an accredited entity from disclosing
 identifiers                                                 unique identifiers to another accredited entity
                                                             or a relying party (other than an accredited
                                                             entity or relying party which provided the
                                                             unique identifier to the accredited entity in the
                                                             first instance).

                                                             Exceptions to this are set out in subsections
                                                             47(4), (5) and (6), and include where disclosure
                                                             of the unique identifier is for the purpose of
                                                             investigating a contravention of the Digital ID
                                                             Act, prosecuting an offence against a law of the
                                                             Commonwealth or state or territory, or to a
                                                             contractor who is engaged by the accredited
                                                             entity to provide all or part of an accredited
                                                             service.
 Sections 48 – 52:             Collection – APP 3            S 48 prohibits the handling of biometric
 Sections governing                                          information unless the handling is specifically
                               Disclosure – APP 6
 the handling of                                             authorised by ss 49 and 50, and in some cases,
 biometric                     Retention and                 only if express consent is also obtained. Due to
 information                   Destruction– APP              their prescriptive nature, these sections
                               11.2                          override APP3, APP6 and APP 11.1 in relation to
                                                             the handling of biometric information.

                                                             S 51 overrides APP 11.2 in relation to the
                                                             retention and destruction of biometric
                                                             information as it contains specific timeframes


Interaction between the Digital ID Act and the Privacy Act                                                Page 3
oaic.gov.au
                                                                                                  November 2024


                                                             for destruction which are more immediate than
                                                             those set out in APP 11.2. It also requires
                                                             destruction rather than allowing
                                                             deidentification as an alternative.
 Section 53:                   Disclosure – APP 6            S 53 overrides APP 6 in this situation by
 Prohibition on data                                         providing only a very limited number of
 profiling to track                                          exceptions at subsection 53(3) where online
 online behaviour                                            behavioural data can be used or disclosed by
                                                             the accredited entity.
 Section 54:                   Disclosure – APP 6            By restricting the use and disclosure of
 Prohibition on                                              personal information for enforcement related
 handling of                                                 activities to a limited number of prescribed
 personal                                                    circumstances, s 54 overrides APP 6 which
 information for                                             allows personal information to be handled in a
 enforcement                                                 broader range of situations.
 purposes
 Section55:         Direct Marketing –                       S 55 overrides APP 7 by only allowing handling
 Prohibition on     APP 7                                    of personal information for marketing
 handling personal                                           purposes, where the information is disclosed to
 information for                                             an individual for the purposes of offering to
 marketing purposes                                          supply the entity’s accredited services, or
                                                             advertising or promoting those services, and
                                                             the information is disclosed to the individual
                                                             with their express consent.
 Section 56:                   Destruction – APP             S 56 overrides APP 11.2 for accredited identity
 Prohibition on the            11.2                          exchange providers in relation to the retention
 retention of certain                                        of certain attributes, by prohibiting retention
 attributes by an                                            after the end of an authentication session (as
 accredited identity                                         defined in the Digital ID (Accreditation) Rules
 exchange provider                                           2024) rather than applying a ‘reasonable steps’
                                                             requirement as set out in APP 11.2.
 Section 136:                  Destruction – APP             S 136 overrides APP 11.2 for accredited entities
 Destruction or de-            11.2                          that hold an approval to participate in the
 identification of                                           AGDIS (or whose approval is
 information by                                              suspended/revoked) in relation to the
 AGDIS participants                                          information outlined in the section.


Interaction between the Digital ID Act and the Privacy Act                                               Page 4
oaic.gov.au
